SC-200 · Question #180
You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution. You need to locate alerts that indicate the use of the…
The correct answer is B. Intent. In the JSON representation of Microsoft Defender for Cloud alerts, the 'Intent' field maps directly to MITRE ATT&CK tactics (e.g., Reconnaissance, Lateral Movement, Privilege Escalation, Exfiltration). To find alerts associated with the Privilege Escalation tactic, you search…
Question
You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution. You need to locate alerts that indicate the use of the Privilege Escalation MITRE ATT&CK tactic. Which JSON key should you search?
Options
- ADescription
- BIntent
- CExtendedProperies
- DEntities
How the community answered
(17 responses)- B94% (16)
- D6% (1)
Explanation
In the JSON representation of Microsoft Defender for Cloud alerts, the 'Intent' field maps directly to MITRE ATT&CK tactics (e.g., Reconnaissance, Lateral Movement, Privilege Escalation, Exfiltration). To find alerts associated with the Privilege Escalation tactic, you search the 'Intent' key for that value. 'Description' contains human-readable text, 'ExtendedProperties' holds additional metadata, and 'Entities' lists affected resources - none of these directly encode the MITRE tactic.
Topics
Community Discussion
No community discussion yet for this question.